Red Hat Security Advisory: Red Hat Satellite 6 security, bug fix, and enhancement update
🔗 CVE IDs covered (9)
📋 Description
CVE-2016-10516 — python-werkzeug: Cross-site scripting in render_full function in debug/tbtools.py CVE-2016-10745 — python-jinja2: Sandbox escape due to information disclosure via str.format CVE-2018-16470 — rubygem-rack: Buffer size in multipart parser allows for denial of service CVE-2018-1000632 — dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents CVE-2019-3893 — foreman: Recover of plaintext password or token for the compute resources CVE-2019-10198 — foreman: authorization bypasses in foreman-tasks leading to information disclosure CVE-2019-10906 — python-jinja2: str.format_map allows sandbox escape CVE-2019-12387 — python-twisted: Improper neutralization of CRLF characters in URIs and HTTP methods CVE-2019-14825 — katello: registry credentials are captured in plain text during repository discovery
🎯 Affected products200
- Red Hat Satellite 6.6
- Red Hat Satellite Capsule 6.6
- ansible-runner-0:1.3.4-2.el7ar.noarch as a component of Red Hat Satellite 6.6
- ansible-runner-0:1.3.4-2.el7ar.noarch as a component of Red Hat Satellite Capsule 6.6
- ansible-runner-0:1.3.4-2.el7ar.src as a component of Red Hat Satellite 6.6
- ansible-runner-0:1.3.4-2.el7ar.src as a component of Red Hat Satellite Capsule 6.6
- ansiblerole-foreman_scap_client-0:0.0.3-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- ansiblerole-foreman_scap_client-0:0.0.3-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.6
- ansiblerole-foreman_scap_client-0:0.0.3-1.el7sat.src as a component of Red Hat Satellite 6.6
- ansiblerole-foreman_scap_client-0:0.0.3-1.el7sat.src as a component of Red Hat Satellite Capsule 6.6
- ansiblerole-insights-client-0:1.6-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- ansiblerole-insights-client-0:1.6-2.el7sat.noarch as a component of Red Hat Satellite Capsule 6.6
- ansiblerole-insights-client-0:1.6-2.el7sat.src as a component of Red Hat Satellite 6.6
- ansiblerole-insights-client-0:1.6-2.el7sat.src as a component of Red Hat Satellite Capsule 6.6
- candlepin-0:2.6.9-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- candlepin-0:2.6.9-1.el7sat.src as a component of Red Hat Satellite 6.6
- candlepin-selinux-0:2.6.9-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- createrepo_c-0:0.7.4-1.el7sat.src as a component of Red Hat Satellite 6.6
- createrepo_c-0:0.7.4-1.el7sat.src as a component of Red Hat Satellite Capsule 6.6
- createrepo_c-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite 6.6
- createrepo_c-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite Capsule 6.6
- createrepo_c-debuginfo-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite 6.6
- createrepo_c-debuginfo-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite Capsule 6.6
- createrepo_c-libs-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite 6.6
- createrepo_c-libs-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite Capsule 6.6
- foreman-0:1.22.0.32-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-0:1.22.0.32-1.el7sat.src as a component of Red Hat Satellite 6.6
- foreman-0:1.22.0.32-1.el7sat.src as a component of Red Hat Satellite Capsule 6.6
- foreman-bootloaders-redhat-0:201901011200-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-bootloaders-redhat-0:201901011200-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.6
- +170 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.6/html/upgrading_and_updating_red_hat_satellite/updating_satellite_server_capsule_server_and_content_hosts Workaround: If you don't want or you cannot upgrade Jinja2, you can override the `is_safe_attribute` method on the sandbox and explicitly disallow all `format` attributes on strings. Workaround: Do not grant the "destroy_compute_resource" permission to users that should not know the password. Workaround: If you cannot upgrade python-Jinja2, you can override the `is_safe_attribute` method on the sandbox and explicitly disallow the `format_map` method on string objects.
🔗 References (119)
- selfhttps://access.redhat.com/errata/RHSA-2019:3172
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1111223
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152515
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1163020
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1194093
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1336439
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1378579
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1402136
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1465521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1490850
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1503426
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1505932
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1559006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1561876
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1591629
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1593480
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1596411
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1601602
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1608712
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1609371
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1612800
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1620529
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1630548
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1634755
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1643649
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1644201
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1649944
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1650641
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1651389
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1653293
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1658265
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1658284
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1658318
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1658553
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1659979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1671274
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1671318
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1672706
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1673447
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1679225
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1679300
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1684573
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1686514
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1687543
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1687801
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1690070
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1690204
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1691074
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1691443
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1698148
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1698178
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1698182
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1703476
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1705099
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1706265
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1706267
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1706274
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1706277
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1706296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1706721
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1706743
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1707157
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1709761
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1712554
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1712889
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1712985
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1713103
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1713248
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1713274
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1713802
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1714234
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1714604
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1715898
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1716877
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1716900
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1717069
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1717248
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1717883
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1718009
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1718889
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1720200
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1721055
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1722475
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1722713
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1723733
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1724064
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1724739
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1725250
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1725289
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1727320
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1727927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1728289
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1728306
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1729049
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1729130
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1729149
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1729153
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1730397
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1730668
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1731112
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1731639
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1732066
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1732601
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1737488
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1739367
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1739485
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1739712
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1744515
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1746166
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1746175
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1746581
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1747177
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1747654
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1750846
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1751384
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1752256
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_3172.json